Junglewise Threat Intelligence

CVE-1999-0098: Sendmail buffer overflow in SMTP HELO command

CVE-1999-0098 · Severity: critical · CVSS 10 · Published 1998-04-01

Technologies: Sendmail. Vendors: Apple.

Executive brief

A critical vulnerability exists in Sendmail, a widely used mail transfer agent responsible for delivering email across the internet. By sending a specially crafted greeting command, a remote attacker can cause a system error that allows them to hide their activities or potentially gain full control over the mail server. This could lead to unauthorized access to sensitive communications, service disruption, or the use of the server for further malicious attacks.

Technical details

A buffer overflow vulnerability exists in the Sendmail SMTP service during the processing of the HELO command. The flaw is rooted in insufficient bounds checking when handling the hostname argument provided during the initial SMTP handshake. A remote, unauthenticated attacker can exploit this by sending an oversized or specially crafted HELO string over the network. Successful exploitation can lead to memory corruption, allowing the attacker to mask malicious activities or achieve full remote code execution with the privileges of the Sendmail process.

Affected products

  • Sendmail Sendmail

Timeline

  • 1998-04-01: disclosed: Initial publication date in NVD.

References